Windows Jump List Parser
Decode AutomaticDestinations and CustomDestinations jump list artifacts — LNK metadata, timestamps, hostnames and pinned items.
100% client-side. Files are parsed locally with WebAssembly and never leave your browser.
Drop jump lists, a folder or a ZIP collection here
*.automaticDestinations-ms, *.customDestinations-ms, KAPE / Velociraptor ZIPs or a whole user profile — or click to choose files
The sample is synthetic: jump lists from a fictional intrusion — no real data. Tip: select creds.txt and use Around… (±5 min) in the time range.
How to get your data
Zero to parsed in under two minutes — pick the first method that fits.- Collect the jump lists
- Drop the folder or ZIP here
- Everything stays in your browser
Prerequisite: Windows PowerShell opened with “Run as administrator” (right-click Start → Terminal (Admin) / Windows PowerShell (Admin)). Paste the whole block.
All users, from a shadow copy (recommended)
$ErrorActionPreference = 'Stop'
New-Item -ItemType Directory -Force C:\triage | Out-Null
$s = Invoke-CimMethod -ClassName Win32_ShadowCopy -MethodName Create -Arguments @{ Volume = 'C:\' }
$v = Get-CimInstance Win32_ShadowCopy | Where-Object ID -eq $s.ShadowID
if (-not $v) { throw 'Shadow copy failed: run PowerShell as administrator' }
cmd /c mklink /d C:\triage\vss "$($v.DeviceObject)\"
Get-ChildItem C:\triage\vss\Users -Directory | Where-Object { -not ($_.Attributes -band [IO.FileAttributes]::ReparsePoint) -and (Test-Path "$($_.FullName)\AppData\Roaming\Microsoft\Windows\Recent") } | ForEach-Object {
robocopy "$($_.FullName)\AppData\Roaming\Microsoft\Windows\Recent" "C:\triage\JumpLists\Users\$($_.Name)" *.automaticDestinations-ms *.customDestinations-ms /S /B /R:0 /W:0 /NJH /NP
}
cmd /c rmdir C:\triage\vss
$v | Remove-CimInstance
Invoke-Item C:\triage\JumpListsTakes a Volume Shadow Copy of C: so files held open by explorer.exe are copied intact, copies both folders of every profile to C:\triage\JumpLists\Users\<user>\, then deletes the shadow copy and opens the folder.
Only your own profile, no admin
robocopy "$env:APPDATA\Microsoft\Windows\Recent" "C:\triage\JumpLists\Users\$env:USERNAME" *.automaticDestinations-ms *.customDestinations-ms /S /R:0 /W:0 /NJH /NPPlain live copy in a normal PowerShell window. Fine for a quick look; a file explorer.exe is writing at that moment can be skipped or come out empty.
→ Then drag the C:\triage\JumpLists folder onto the drop zone (or zip it first to move it; a ZIP made with PowerShell's Compress-Archive works too).
Gotchas
- Live copies can come out empty (0 bytes) when explorer.exe holds the file — use the shadow-copy command, KAPE or an image; the parser flags empty files.
- Reading other users' profiles needs an elevated (administrator) prompt; without it you only get your own.
- Timestamps are stored in UTC; entries age out and users can clear lists, so an empty or short list is itself a finding.
- 010 bytes uploaded
- 02Windows 7 – 11
- 03Automatic + Custom destinations
- 04700+ known AppIDs
Everything a jump list remembers
Every entry is a waypoint: a file, folder or task the user jumped to, stamped with when they were last there.
DestList timeline
When each item was last opened, its entry number and pin state, straight from the DestList stream.
Embedded LNK metadata
Target path, created / modified / accessed times, size, attributes, volume serial, label and drive type.
AppID resolution
700+ known AppIDs turn the 16-hex-digit file name into the application that owned the list.
Machine & tracker data
NetBIOS hostname and the MAC address from the LNK tracker block — spot items opened from another machine.
Tasks and arguments
CustomDestinations categories, task descriptions and command-line arguments, including browser URLs.
Private by design
A Rust parser compiled to WebAssembly. Files never leave the tab, and it keeps working offline.
From collection to answer in three steps
- 1
Collect
Grab AutomaticDestinations and CustomDestinations from each user profile — live, from a shadow copy or a forensic image.
- 2
Drop
Drag the files onto the page. Parsing runs locally in WebAssembly in a fraction of a second.
- 3
Investigate
Sort by last used, filter by application or path, inspect every LNK field and export JSON or CSV.
Related tools
Artifacts that answer the next question in the same case.
Questions investigators ask
Are my files uploaded anywhere?
No. The parser is compiled to WebAssembly and runs inside your browser tab. There is no upload endpoint — you can load the page, disconnect from the network and keep parsing.
AutomaticDestinations or CustomDestinations — what's the difference?
AutomaticDestinations are OLE containers the shell maintains for recent and frequent items, with a DestList stream holding last-used times and pins. CustomDestinations are written by the application itself: tasks, custom categories and pinned items.
What does the AppID in the file name tell me?
The 16-hex-digit prefix identifies the application that owns the list (for example 5f7b5f1e01b83767 is Quick Access). The parser resolves 700+ known AppIDs; keep the original file names when you collect.
Which timestamp says when a file was last opened?
The DestList "last used" time of an AutomaticDestinations entry. The created / modified / accessed times come from the embedded LNK and describe the target file itself.
Do deleted or moved files still show up?
Yes. Entries persist after the target is deleted, renamed or on a removed USB drive, until the list is cleared or the entry ages out — which is exactly why jump lists matter in an investigation.